Performing the initial NDR Console configuration

Prev Next

Before you deploy your virtual NDR Console appliance, make sure the following requirements are met.

Wizard steps

The following table describes the questions the configuration wizard prompts you to answer.

Note

This topic uses example values in bold for illustration.

Prompt

Action

This is the first boot of your new IA.

You must accept the FireEye End User License Agreement before you can continue.

Press <return> to display EULA.

  1. Press the Enter key.

  2. Read the EULA at http://www.fireeye.com/company/legal.

  3. Press Q to leave this screen and proceed to the next screen.

Type "accept" to accept the agreement.

Type "eula" to review the EULA again. Type "no" if you do not accept the agreement.

*Typing "no" will cause the system to halt.

Do you accept the FireEye End User License Agreement?: accept

Type one of the options the prompt presents.

Configuring IA time preferences:

The current time zone is set to "UTC (UTC, +0000)"

Would you like to change the time zone? [y/N]: N

Enter y to change the time zone from UTC or N to keep the UTC time zone.

The current time is Mon Jul 25 17:08:17 UTC 2019

Would you like to change the time? [y/N]: N

Enter y to change the displayed current time or N to keep the current time.

Configuring IA network:

Pressing return without entering a new value will use the default values.

Hostname [ IA ]: IA -16

Specify the host name.

Fully qualified hostname []:

(Optional): Specify the fully qualified domain name (FQDN).

Configure network devices. DHCP or static devices with an IP address or Netmask will not be available for capture.

Configure ether1 interface?

  1. static

  2. dhcp

  3. disbaled

[1/2/3]: 1

Enter 1 or 2 to configure the first interface (for the management port, indicated by MGMT).

Note

Do not disable this interface.

Routable IP address (dotted quad)

[10.0.0.1]: 10.128.44.82

If you entered 1 at the previous prompt, enter an accessible IPv4 address in the specified format.

IPv4 netmask (dotted quad)

[255.255.255.0]: 255.255.255.0

Enter the netmask for the IP address in the specified format.

Routable IPv6 address []:

IPv6 prefix length []:

Press Enter twice to skip this configuration.

Configure ether2 interface?

  1. static

  2. dhcp

  3. disabled

[1/2/3]: 3

Enter 3 to disable the second interface (for the capture port).

Please select an available capture device- you may select up to 4 more (enter q if done selecting).

  1. ether1 (has IP/NM)

  2. ether2 (Available)

    [2]: 2

Configure the capture interface. If multiple interfaces are available, choose one contiguous to the management interface.

Please select an available capture device - you may select up to 4 more (enter q if done selecting).

  1. ether1 (has IP/NM)

  2. ether2 (Available)

[2]: 2

Configure the capture interface. If multiple interfaces are available, choose one contiguous to the management interface.

IPv6 Gateway []:

Press Enter to skip this configuration.

Enter each DNS server on a separate line.

Blank line to exit

DNS server: 10.128.11.100

DNS Server:

Enter each DNS server on a separate line. Press Enter when you are finished to proceed to the next prompt.

Enter each Search domain on a separate line. Blank line to exit

Search domain: it.acme.com

Search domain:

Enter each search domain on a separate line. Press Enter to proceed to the next prompt.

Enter each NTP server on a separate line.

Blank line to exit.

NTP server: 0.pool.ntp.org

NTP server:

Enter each NTP server on a separate line. Press Enter to proceed to the next prompt.

HOSTNAME: IA -16

FQDN:

ether1: enabled, static

IPv4: 10.128.44.82

netmask: 255.255.255.0

IPv6: prefix length:

ether2: disabled

Capture Device: ["ether2"]

GW: 10.128.44.1

GW6:

DNS: 10.128.11.100

Search Domains: it.acme.com

NTP: 0.pool.ntp.org

SAN_ENABLED: false

Accept values as shown? [y/N]: y

Review the information and then enter y to accept the values or N to return to the wizard and change them.

Configured data storage found - rebuild required

Do you want to encrypt storage? [y/N]:

Enter y.

Would you like to change the npadmin, npscp, and c IA account password? [y/N]:

Enter y to be prompted to change the password or N to accept the default password of "hammerhead" for these three accounts and change them later.

Rebooting to apply the new settings.

...

Wait for the instance to finish rebooting.